Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip, an open-source control plane for AI agent teams, allowed attackers to execute commands on network servers or developer computers. These vulnerabilities were exploitable by importing and starting a malicious agent. A third flaw could expose sensitive data and control-plane details through API routes. The extent of exploitation was not disclosed.

Severity: Critical · Category: Supply Chain

Impact: Command execution on network servers/developer machines, sensitive data exposure.

Source: The Hacker News · Aug 05 2026 · Original source

What Happened

Two security flaws in Paperclip, an open-source control plane for teams of artificial intelligence (AI) agents, allowed attackers to execute commands on a network server or a developer's computer. Both vulnerabilities relied on importing a malicious agent and subsequently starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes that did not enforce expected access checks.

The more severe server-side path, tracked as CVE-2026-41679, allowed command execution without a pre-existing account or victim interaction against network-accessible deployments using authenticated mode with the default registration configuration. The second path, tracked as GHSA-x8hx-rhr2-9rf7, required a user to open an attacker-controlled page while Paperclip was running in its default local_trusted mode.

Timeline

Technical Analysis

The underlying product property connecting the findings was that agent configuration could become executable behavior, as Paperclip's built-in process adapter intentionally launches a configured command as a child process of the server. The vulnerabilities changed who could reach this execution feature and whose configuration the server would trust, allowing unauthorized users or browser-originated requests to introduce and activate configuration that reached the launcher.

For CVE-2026-41679, the server-side chain exploited Paperclip's default open-signup flow. An attacker could register, sign in, and activate a durable board API credential without administrator approval. While this credential should not have been sufficient to create a top-level company, the new-company import route accepted board-level access. An attacker could then supply a `.paperclip.yaml` bundle defining a new company, an agent using the process adapter, and the command for that agent to run. The import made the attacker a member of the new company, allowing the wakeup check to pass and Paperclip to launch the command with the operating-system privileges of its server process.

For GHSA-x8hx-rhr2-9rf7, the localhost chain targeted Paperclip's default local_trusted configuration, which binds to the loopback interface and historically treated every request as an implicit instance administrator. Oasis Security demonstrated a Domain Name System (DNS) rebinding attack where an attacker-controlled hostname resolved to both the attacker's server and 127.0.0.1. A browser would load JavaScript from the attacker's server, and subsequent requests to the same hostname would reach the local Paperclip service while still being considered same-origin. Paperclip accepted the attacker's hostname in the Host header, allowing the page to call Paperclip's import API, install a company with a process-based agent, and invoke its wakeup endpoint. Local mode assigned administrator authority to these rebound requests, leading the server to run the attacker's command with the developer's privileges.

The third advisory, GHSA-xfqj-r5qw-8g4j, covered several API routes in authenticated mode that failed to consistently reject unauthenticated or cross-company requests. This design allowed an unauthenticated request to continue through middleware with a "no actor" identity, requiring each route to remember its own assertion. Specific instances included a caller with a valid heartbeat-run identifier retrieving associated issue data without company access, and other routes disclosing agent-facing skill documentation (API paths, authentication conventions) or health information (deployment mode, version, authentication readiness, bootstrap state, exposure, and feature flags). The unauthenticated CLI challenge route also formed part of the credential-generation chain used by CVE-2026-41679.

Impact

The vulnerabilities allowed command execution on network servers or developer computers. The server-side path (CVE-2026-41679), with a CVSS score of 10.0, required no pre-existing account or victim interaction against network-accessible deployments. The localhost path (GHSA-x8hx-rhr2-9rf7), with a CVSS score of 9.6, required a user to open an attacker-controlled page. The practical impact of command execution could include access to application data, source repositories, locally stored credentials, secrets available to agent processes, and internal services reachable from the affected machine.

The third flaw (GHSA-xfqj-r5qw-8g4j), with a CVSS score of 8.3, exposed sensitive data and control-plane details. This included the retrieval of heartbeat issue data with a valid run identifier but without company access, and the disclosure of Paperclip's agent-facing skill documentation (including API paths and authentication conventions) and health information (such as deployment mode, version, authentication readiness, bootstrap state, exposure, and feature flags) via unauthenticated or cross-company requests. As of August 5, 2026, no authoritative source reviewed by The Hacker News reported exploitation in the wild.

Discovery & Response

Oasis Security's analysis, backed by a 17-page technical report, connected the findings. Paperclip v2026.416.0 contains fixes for the import-authorization and hostname-validation issues. For CVE-2026-41679, the fix requires instance-administrator access for imports targeting a new company and company access for imports targeting an existing one, with this check now protecting both import preview and execution. Open registration remains available, but a newly registered board user can no longer treat the new-company import route as an instance-administrator operation.

For GHSA-x8hx-rhr2-9rf7, the direct fix was hostname validation. Paperclip's source tagged as v2026.416.0 enables a private-hostname guard for private deployments running in either local_trusted or authenticated mode. This guard runs before the middleware that assigns an identity to the request, rejecting rebound requests carrying an unapproved hostname before they reach the API. For GHSA-xfqj-r5qw-8g4j, Paperclip added authentication to general skill routes, company-access checks to heartbeat issue retrieval, invite-scoped onboarding routes, and a reduced health response for unauthenticated users.

Rapid7 published a Metasploit module for CVE-2026-41679, which automates the six-request attack chain. CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) enrichment carried by NVD classifies exploitation as proof-of-concept and marks the flaw as automatable with total technical impact. The vulnerability was not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog when checked on August 5, 2026.

How Fencio prevents this

The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.

Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.

All incidents